CVE-2026-102365: Gz-Yami MALL4J

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.

Affected products

  • Gz-Yami MALL4J: up to and including 4.0

Published 2026-09-29. Last modified 2026-10-01.